CVE-2026-7189

HIGH

Sensitive Data Exposure in Proliz's OBS

Title source: cna
STIX 2.1

Description

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 15.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (1)
Proliz Software Ltd. Co./Proliz's OBS < v3.6.0
Published Jul 17, 2026
Tracked Since Jul 17, 2026